Tag: .NET
All the articles with the tag ".NET".
-
System.Text.Json Polymorphic Deserialization
Updated:Deserialize JSON into derived or abstract types: $type discriminators, [JsonPolymorphic] in .NET 7+, and a custom JsonConverter for legacy payloads.
-
Fix CS8618 Nullable Warnings in C# JSON Models
Updated:Fix CS8618 non-nullable property warnings in C# JSON DTOs: compare nullable properties, constructors, default values and required, and why default! is risky.
-
What is IdentityServer and When Do You Need it?
Updated:IdentityServer is a .NET SDK for building an OpenID Connect and OAuth 2.0 identity provider on ASP.NET Core, issuing tokens to multiple clients and APIs. You need it for several apps or APIs, single sign-on, federation, or standards-based tokens. A single app with local users doesn’t; ASP.NET Core Identity suffices.
-
Run a .NET App as a Linux Service with systemd
Updated:Run a .NET app as a Linux service: add Microsoft.Extensions.Hosting.Systemd, call UseSystemd(), write a Type=notify unit file, and read logs via journald.
-
Using ASP.NET Core Passkeys for Second Factor Authentication
You can use passkeys as a second factor after password login in ASP.NET Core Identity on .NET 10. Register a two-factor token provider for users who have a passkey, then add two endpoints: one creates passkey request options for the user who passed the password check, and the other verifies the passkey before completing sign-in. Store the user id from the password step in a short-lived cookie, and compare it with the passkey’s user before signing in.
-
Device Bound Session Credentials in ASP.NET Core
A session cookie is a bearer token, which is a polite way of saying that whoever holds it is you. Copy the cookie, replay it from another machine, and the server happily serves your account. Nothing about the request proves which device it came from, so a cookie lifted by malware, an XSS payload, or a stray database backup keeps working until it expires. For a long-lived session, that can be weeks.
-
Building a Supply Chain Attack with .NET and NuGet
Every time npm has a supply chain incident, it’s tempting to think “haha, npm had yet another supply chain attack!” and feel safe in .NET land. But the tools to do the same thing in .NET, or at least similar things, are all there. Module initializers, source generators, MSBuild targets, startup hooks. A number of techniques exist to smuggle code into someone’s codebase, and most of them run before your application’s Main method is even called.
-
Hosting the .NET Aspire Dashboard as a Standalone Container in Azure Web Apps
Sometimes you just want a simple way to look at your traces, metrics, and logs without setting up a full observability stack. Just a UI where you can see what your applications are doing, without having to setup Azure Monitor, Grafana, Prometheus, Jaeger, etc. You don’t always need durability or complex infrastructure.
-
Keyed Services (Named registrations) in .NET Service Provider
You have an IMessageSender interface, with two implementations: EmailMessageSender and SmsMessageSender. You register both, and now the question is which one gets injected into your OrderConfirmationService constructor. The answer, unhelpfully, is whichever was registered last. This may also introduce subtle, unexpected bugs when new services are registered.
-
TimeProvider and the End of Untestable DateTime.Now
DateTime.Now is one of those calls that looks harmless until you try to write a test around it. It’s a static property that reads the system clock, and there’s no way to control what it returns without wrapping it in something injectable. I have wrapped it in codebases, and others have too. Unfortunately, everyone wrapped it their way. Since .NET 8, we can all stop reinventing the same abstraction and use TimeProvider instead.